logg.money
Sign In

Last updated 29 August 2026

Privacy Policy

logg.money reads your bank transaction messages so you do not have to type expenses in by hand. That means it handles genuinely sensitive material, so this page states plainly what is collected, where it is sent, and how to get rid of it.

01Who this covers

This policy applies to the logg.money website and app. It describes how the service handles information about you when you create an account and connect a source of transactions.

logg.money is an independent product, not a bank, a payment processor, or a licensed financial adviser. It never moves money and never has the ability to.

02What is collected

  • Account details. Your email address, and your phone number if you choose to receive confirmations over WhatsApp.
  • Bank transaction SMS. Messages you forward from your phone, typically through an iOS Shortcut. These contain an amount, a merchant, a masked account number, and a reference.
  • Email transaction records. If you connect Gmail, the content of messages identified as receipts, payment confirmations, or bank statements. See clause 3.
  • Bank statement files. PDF statements you upload. If a statement is password-protected, the password you supply is stored so later statements from the same bank can be opened without asking again.
  • Derived expense records. The structured result — merchant, amount, category, date, account — extracted from the above, plus any corrections you make.

There is no advertising identifier, no third-party analytics fingerprinting, and no tracking of your activity on other sites.

03How Gmail access is used

Connecting Gmail is optional, and the service requests exactly one Google scope: gmail.readonly. That grants permission to read messages. It grants no ability to send, modify, archive, or delete anything in your mailbox, and the service does not ask for a broader scope.

Access is used for a single purpose: locating transaction and receipt emails and extracting the expense details from them. Message content is not read for any other reason, is not used to build an advertising or marketing profile, is not sold, and is not used to train general-purpose AI models.

You can disconnect Gmail at any time from the app, or revoke access directly in your Google account's security settings. Revoking stops all further reading immediately.

04Who else sees it

Extracting an expense from a bank message is done by a language model, which means the text of that message is sent to a model provider. The providers used are:

  • Google (Gemini). Parsing and categorisation, via generativelanguage.googleapis.com.
  • OpenRouter. Used as a routing layer for the same purpose when a request is served by an alternative model.
  • Supabase. Database, authentication, and file storage.
  • Meta (WhatsApp) and Telegram. Only if you enable notifications, and only to deliver the confirmation message to you.

These are processors: they handle the data to provide the feature, not for their own purposes. Your data is not sold, rented, or shared with advertisers or data brokers, and there is no arrangement under which anyone pays for access to it.

05How it is stored

Records are held in a Postgres database with row-level security, so a query authenticated as you can only return your own rows. Google OAuth tokens are encrypted at rest rather than stored as plain text. Uploaded statement files are held in private storage, not in a public bucket.

No system is immune to compromise, and this one is operated by a single developer. What is claimed here is the measures actually in place, not a guarantee of outcome.

06Keeping and deleting

Expense records are kept while your account exists, because the point of the product is a history you can look back through. Raw source material — the original SMS or email text — is kept alongside the derived record so that a wrong extraction can be diagnosed and corrected.

There is no self-service delete button in the app yet. To have your account and its data deleted, email hello@logg.money from the address on the account. Deletion covers the derived records, the stored source messages, uploaded statements, saved statement passwords, and the Google token. It is honoured within 30 days.

07What you control

  • Disconnect a source. Gmail can be disconnected in the app or revoked in your Google account. You can stop forwarding SMS at any time by removing the Shortcut.
  • Correct a record. Any field the model got wrong can be edited, and the correction is what is kept.
  • Get a copy. Ask at hello@logg.money and you will be sent an export of your records.
  • Delete everything. As described in clause 6.

Depending on where you live you may have further statutory rights — for example under the GDPR or India's Digital Personal Data Protection Act — including objecting to processing or lodging a complaint with a supervisory authority. Requests under any of these go to the same address.

08Not for children

The service is not directed at children under 13 and accounts are not knowingly created for them. If you believe a child has an account, write to hello@logg.money and it will be removed.

09Changes to this policy

If this policy changes in a way that materially affects how your data is handled, the date at the top of the page changes and account holders are notified by email. Continuing to use the service after that constitutes acceptance.

10Contact

Questions, requests, and complaints: hello@logg.money.

logg.money is built and operated by an independent solo developer, not by a company. Every request described above is read and answered by that one person, which is both why replies are not instant and why nobody else has a reason to look at your data.